reason:
In order to restrict the user access Address Lists, I modified the security settings of the Address Lists in Exchange Server Manager, but incorrectly rejected the access permission of Authenticated Users.
Because Administrator belongs to the Authenticated User Group, you can't access the Administrator to use Administrator ... Don't say administrator, any verification user has no way to access, so add new admin can not work.
solve:
I have been in two hours, I decided to sleep, as a result, I thought in the morning.
Guest users are not Authenticated Users, so they can get around ... But the guest users do not have any modification rights, what is the use?
Schema admin Users can modify the AD architecture, so we temporarily add Guest to the reorganization. It is recommended to limit the network access, operate on a single machine, avoid risk.
Open the Adsiedit tool using the RunaS method,
CN = All address Lists, CN = Microsoft Exchange, CN = Services, CN = Configuration, DN =
DN =
DN =
As you know, DN represents your domain name and adjusts according to the actual situation.
Modify security settings to restore administral management.
Finally, don't forget to recover the Guest's permissions, or you will wait for the machine to be hijacked, huh, huh
postscript:
It's so tired to save a MSDN's case.